Alerts This Week
Warning Icon 1 916
Alerts This Week
Warning Icon 1 916

Debian 10: DLA-3126-1 Critical: Libsndfile Out-of-Bounds Read

debian lts
Calendar Grey September 29, 2022
Dist Debian Esm H88
Enhance libsndfile to address a potential out-of-bounds read vulnerability that could expose confidential information. Maintain security through Debian LTS patches.
An issue has been found in libsndfile, a library for reading/writing audio files

Summary

An issue has been found in libsndfile, a library for reading/writing audio
files.

Using a crafted FLAC file, an attacker could trigger an out-of-bounds read
that would most likely cause a crash but could potentially leak memory
information.


For Debian 10 buster, this problem has been fixed in version
1.0.28-6+deb10u2.

We recommend that you upgrade your libsndfile packages.

For the detailed security status of libsndfile please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/source-package/libsndfile

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS



Severity
critical
Lowest
Low
Medium
High
Critical

Package: libsndfile
Version: 1.0.28-6+deb10u2
CVE ID: CVE-2021-4156

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here